Connect with us

Hi, what are you looking for?

Top Stories

Microsoft Blocks Unauthorized Scripts in Entra ID, ASUS Patches Critical AiCloud Vulnerability

Microsoft will block unauthorized scripts in Entra ID by late 2026 to combat XSS attacks, enhancing security during user logins while ASUS patches critical AiCloud vulnerabilities.

Microsoft is set to enhance security for its Entra ID platform by blocking unauthorized script injections during user logins, with the update scheduled for late 2026. This initiative, part of the company’s Secure Future Initiative, will implement a stricter Content Security Policy for sign-ins at login.microsoftonline.com, permitting scripts solely from trusted Microsoft domains. The move aims to mitigate risks associated with cross-site scripting (XSS) attacks and prevent unauthorized code from executing during the authentication process. Importantly, this update will not affect external identity sign-ins. Microsoft has advised organizations to proactively test their sign-in flows and refrain from using browser extensions that inject scripts, recommending alternatives that do not alter the Entra login experience.

In parallel, a bipartisan legislative effort known as the AI Fraud Deterrence Act has been introduced by Representatives Ted Lieu (D-Calif.) and Neal Dunn (R-Md.). This bill seeks to impose harsher criminal penalties for fraudulent activities facilitated by artificial intelligence tools, such as convincing fake audio, video, or text communications. Under the proposed legislation, the fines for mail, wire, and bank fraud, as well as for money laundering, could reach between $1 million and $2 million. Moreover, utilizing AI in fraudulent impersonations of government officials may incur a maximum fine of $1 million and a prison sentence of up to three years. The lawmakers emphasized the need for stringent measures as AI technology increasingly aids scammers.

ASUS has responded to cybersecurity threats by rolling out firmware updates that address nine vulnerabilities within its AiCloud feature, which allows routers to function as personal cloud servers. Notably, one critical vulnerability, assigned a CVSS score of 9.2, pertains to an authentication bypass that can be triggered inadvertently through Samba functionality. This discovery raises concerns about the potential for unauthorized access to sensitive functions. The company’s advisory underscores the importance of updating affected devices to mitigate security risks.

In another notable development, OpenAI has severed ties with Mixpanel following a data breach that compromised the personal information of API users, affecting approximately 35,000 individuals. Mixpanel reported the breach to OpenAI on November 25, with the exposed data including names, email addresses, locations, system details, and account IDs. While regular ChatGPT users were not impacted, OpenAI has initiated a comprehensive security review of all its vendors and is actively notifying those affected. The company has stated that there is no evidence indicating that the breach extends beyond Mixpanel’s environment, reaffirming its commitment to transparency and robust security measures.

The cybersecurity landscape remains cautious as three London councils—Royal Borough of Kensington and Chelsea, Westminster City Council, and the Borough of Hammersmith and Fulham—have been affected by an incident involving their shared IT services. Although details are still emerging, the incident has prompted these authorities to take precautionary measures by shutting down certain IT systems. It is currently premature to attribute the incident to a specific threat actor or to confirm data compromise.

Dartmouth College has also experienced a significant data breach linked to a campaign involving Oracle E-Business Suite, impacting over 35,000 individuals across multiple states. The breach reportedly occurred between August 9 and August 12, with unauthorized access resulting in the theft of sensitive information, including Social Security numbers and financial account data. College officials have commenced an investigation to assess the full extent of the breach.

Meanwhile, Microsoft is investigating a service outage affecting its Exchange Online platform, which has been blocking user access to Outlook mailboxes. Reports indicate that the outage began on Tuesday and has primarily impacted users in the Asia Pacific and North America regions attempting to connect via the classic Outlook desktop client. Microsoft has yet to disclose the number of users affected, but the disruption has caused server connection and login issues for many.

Further complicating matters for Windows users, Microsoft has issued a warning regarding recent changes to FIDO2 security keys. Following updates released since the September 2025 preview update, users may now be prompted to enter a PIN when signing in. This adjustment is in accordance with WebAuthn specifications, which dictate the handling of user verification requests for various authentication methods. Users are advised that they might need to create a PIN, even if it was not previously required during their initial device registration.

As the cybersecurity landscape evolves, organizations are reminded of the importance of staying vigilant against emerging threats and ensuring robust security protocols are in place.

Staff
Written By

The AiPressa Staff team brings you comprehensive coverage of the artificial intelligence industry, including breaking news, research developments, business trends, and policy updates. Our mission is to keep you informed about the rapidly evolving world of AI technology.

You May Also Like

AI Technology

Cocoon launches a decentralized AI network on TON, enabling GPU owners to profit from rented computing power while prioritizing user privacy and data security.

Top Stories

Microsoft stock trades at 30x earnings, backed by a 40% revenue surge in cloud services, making it a compelling buy amid AI growth prospects.

AI Technology

Amazon, Meta, and other tech giants are set to raise nearly $100 billion in debt to fuel AI and cloud infrastructure, reflecting a critical...

AI Cybersecurity

Microsoft's Digital Crimes Unit targets AI-driven cyber threats with a $20B strategy, aiming to enhance security as AI-related data breaches surge by 80%

AI Technology

IREN partners with Microsoft for a $9.7B deal, aiming to expand its GPU fleet to 140,000 by 2026, marking a pivotal shift from crypto...

Top Stories

Over 1,000 Amazon employees warn the company’s $150 billion AI push threatens jobs, democracy, and the environment, calling for urgent ethical reforms.

Top Stories

OpenAI's latest ChatGPT Android app beta reveals plans to introduce ad features, including a "search ads carousel," targeting commercial queries for revenue generation.

AI Regulation

OpenAI, Google, and Microsoft unite in a groundbreaking AI safety coalition to establish voluntary standards and enhance accountability within six months.

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.